diff options
author | Marc Kleine-Budde <mkl@pengutronix.de> | 2021-07-23 22:17:50 +0200 |
---|---|---|
committer | Tom Rini <trini@konsulko.com> | 2021-07-28 20:46:34 -0400 |
commit | 62b27a561c2868d95445905ad554297e43cc0f2b (patch) | |
tree | 4ed6786f1809fc6d212d157a9683a2ab6409c191 /doc | |
parent | 89795ef3b6b2d12cffb840a98ee374d2e806aa64 (diff) | |
download | u-boot-62b27a561c2868d95445905ad554297e43cc0f2b.zip u-boot-62b27a561c2868d95445905ad554297e43cc0f2b.tar.gz u-boot-62b27a561c2868d95445905ad554297e43cc0f2b.tar.bz2 |
mkimage: use environment variable MKIMAGE_SIGN_PIN to set pin for OpenSSL Engine
This patch adds the possibility to pass the PIN the OpenSSL Engine
used during signing via the environment variable MKIMAGE_SIGN_PIN.
This follows the approach used during kernel module
signing ("KBUILD_SIGN_PIN") or UBIFS image
signing ("MKIMAGE_SIGN_PIN").
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
Diffstat (limited to 'doc')
-rw-r--r-- | doc/uImage.FIT/signature.txt | 4 |
1 files changed, 2 insertions, 2 deletions
diff --git a/doc/uImage.FIT/signature.txt b/doc/uImage.FIT/signature.txt index 7cb1c15..61a72db 100644 --- a/doc/uImage.FIT/signature.txt +++ b/doc/uImage.FIT/signature.txt @@ -533,8 +533,8 @@ Generic engine key ids: or "<key-name-hint>" -As mkimage does not at this time support prompting for passwords HSM may need -key preloading wrapper to be used when invoking mkimage. +In order to set the pin in the HSM, an environment variable "MKIMAGE_SIGN_PIN" +can be specified. The following examples use the Nitrokey Pro using pkcs11 engine. Instructions for other devices may vary. |